9507934

Filtering Mechanism for Securing Linux Kernel

PublishedNovember 29, 2016
Assigneenot available in USPTO data we have
Technical Abstract

Patent Claims
9 claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

1. A device for safeguarding a Linux kernel comprising: a processor; a memory storing instructions to be executed by the processor; applications; a core kernel; a wrapper in communication with the core kernel, the wrapper being object oriented; and a filter in communication with the wrapper and the core kernel, the filter only in indirect communication with all of the applications via the wrapper, the filter being dynamically loadable, the filter further being capable of intercepting function calls prior to the function calls accessing the core kernel.

2

2. The device of claim 1 further comprising: a syscall table in communication with the filter.

3

3. The device of claim 1 further comprising: a userspace and a kernelspace.

4

4. The device of claim 3 wherein the userspace includes an application that issues the function calls.

5

5. The device of claim 3 wherein the kernelspace includes the wrapper, the filter, and the core kernel.

6

6. The device of claim 1 wherein the filter is realized as a decorator class.

7

7. The device of claim 6 wherein a policy is added for each decorator class, each of the policy for each decorator class being capable of determining preconditions.

8

8. The device of claim 1 wherein the wrapper is capable of issuing a trap to the core kernel when an intercepted function call is unauthorized.

9

9. A method for securing a Linux kernel based on dynamically loadable message filters comprising the steps of: intercepting, by a message filter, function calls sent from applications located in a userspace; issuing, by a wrapper, a trap to a core kernel when an intercepted function call is unauthorized; dynamically invoking, by a syscall table, a filter function of the filter corresponding to the intercepted function call, the filter being only in indirect communication with all of the applications via the wrapper; triggering, by the message filter, actions according to policy specifications; and calling, by the wrapper, an original kernel function.

Patent Metadata

Filing Date

Unknown

Publication Date

November 29, 2016

Inventors

Dharanipragada Janakiram

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “FILTERING MECHANISM FOR SECURING LINUX KERNEL” (9507934). https://patentable.app/patents/9507934

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.